Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are known.
References
Link | Resource |
---|---|
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6219_7.10.6_2023-03-20.pdf | Release Notes |
http://seclists.org/fulldisclosure/2023/Jun/8 | Mailing List Third Party Advisory |
http://packetstormsecurity.com/files/173083/OX-App-Suite-SSRF-Resource-Consumption-Command-Injection.html | Third Party Advisory VDB Entry |
https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0002.json |
Configurations
Configuration 1 (hide)
|
History
12 Jan 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
07 Jul 2023, 18:39
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-77 | |
First Time |
Open-xchange
Open-xchange open-xchange Appsuite Backend |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
References | (MISC) https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6219_7.10.6_2023-03-20.pdf - Release Notes | |
References | (MISC) http://seclists.org/fulldisclosure/2023/Jun/8 - Mailing List, Third Party Advisory | |
References | (MISC) http://packetstormsecurity.com/files/173083/OX-App-Suite-SSRF-Resource-Consumption-Command-Injection.html - Third Party Advisory, VDB Entry | |
References | (MISC) https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0002.json - Third Party Advisory | |
CPE | cpe:2.3:a:open-xchange:open-xchange_appsuite_backend:*:*:*:*:*:*:*:* cpe:2.3:a:open-xchange:open-xchange_appsuite_backend:7.10.6:revision_39:*:*:*:*:*:* cpe:2.3:a:open-xchange:open-xchange_appsuite_backend:7.10.6:*:*:*:*:*:*:* |
22 Jun 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
22 Jun 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Jun 2023, 13:03
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-20 08:15
Updated : 2024-01-12 08:15
NVD link : CVE-2023-26429
Mitre link : CVE-2023-26429
JSON object : View
Products Affected
open-xchange
- open-xchange_appsuite_backend
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')